Information Security Analyst

Scale Up Recruiting Partners

Madrid

Presencial

EUR 60.000 - 95.000

Jornada completa

Hace 6 días
Sé de los primeros/as/es en solicitar esta vacante
Generador de candidaturas

Una candidatura completa en un minuto: currículum y carta de presentación adaptados, listos para enviar.

Supera los filtros ATS

Descripción de la vacante

Scale Up Recruiting Partners is assisting a U.S.-based cybersecurity client to hire an Information Security Analyst on a contract basis. The role owns the vendor security questionnaire process across multiple client accounts, coordinating with U.S.-based startups and handling security questionnaires (SIG/CAIQ) using platforms like OneTrust and Whistic.

You will monitor requests, manage tickets in Jira/Linear, maintain knowledge bases, and collaborate with security consultants and engineers to

Formación

  • 2–4 years in vendor security questionnaires or GRC/compliance in a client-facing role.
  • Hands-on experience with SIG, CAIQ, or custom vendor questionnaires.
  • Working knowledge of SOC 2 and ISO 27001.
  • Understanding of security concepts: SSO, MFA, Endpoint Management, Encryption, Cloud basics, Backup/DR, Vendor Risk.
  • Strong organizational skills to manage multiple requests.
  • Good judgment on when to involve technical SMEs.
  • Excellent written communication and professional English.

Responsabilidades

  • Monitor client Slack channels and respond to incoming security questionnaire requests.
  • Create and manage tickets in Jira, Linear, or other ticketing systems to track requests through completion.
  • Complete vendor security questionnaires (SIG, CAIQ, or custom questionnaires) through spreadsheets and security platforms such as OneTrust, Whistic, SecurityScorecard, and similar tools.
  • Develop a deep understanding of each client's security posture, policies, controls, and technical environment.
  • Maintain and continuously improve client answer libraries and knowledge bases.
  • Coordinate with security consultants, engineers, and SMEs for technical clarification.
  • Escalate recurring gaps or missing controls that impact questionnaire responses.
  • Ensure all questionnaires are completed accurately and within customer deadlines.

Conocimientos

Vendor questionnaires
GRC/Compliance
SOC 2 knowledge
ISO 27001 knowledge
Stakeholder coordination
Written communication
English proficiency

Herramientas

Jira
Linear
OneTrust
Whistic
SecurityScorecard

Descripción del empleo

Hey! We're Scale Up, and our client is looking to hire a Information Security Analyst.

Type of Employment: Contractor (Long-term)

Work Modality: 100% Remote

Work Schedule: Full-time

Time Zone: U.S. Pacific Time (PST) with overlap during business hours

About Our Client

Our client is a fast-growing U.S.-based cybersecurity and compliance consulting firm that partners with technology startups to strengthen their security posture and achieve compliance with frameworks such as SOC 2, ISO 27001, HIPAA, and more.

They act as an extension of their clients' security teams, providing GRC consulting, audit readiness, vendor risk management, and virtual CISO services. As the company continues to grow, they are expanding their team with professionals who enjoy working across multiple clients in a fast-paced consulting environment.

About The Role

You'll own the vendor security questionnaire process from end to end across multiple client accounts.

You'll work closely with U.S.-based startups, monitoring incoming security requests, coordinating with technical stakeholders, and completing security questionnaires accurately and on time. This role requires a solid understanding of security frameworks, strong organizational skills, and the ability to communicate clearly with both technical and non-technical stakeholders.

This is an excellent opportunity for someone with experience in GRC, security compliance, or vendor risk who enjoys supporting multiple clients and playing a key role in helping companies close enterprise deals.

Key Responsibilities
  • Monitor client Slack channels and respond promptly to incoming security questionnaire requests.
  • Create and manage tickets in Jira, Linear, or other ticketing systems to track requests through completion.
  • Complete vendor security questionnaires (SIG, CAIQ, custom questionnaires) through spreadsheets and security platforms such as OneTrust, Whistic, SecurityScorecard, and similar tools.
  • Develop a deep understanding of each client's security posture, policies, controls, and technical environment.
  • Maintain and continuously improve client answer libraries and knowledge bases.
  • Coordinate with security consultants, engineers, and subject matter experts whenever technical clarification is needed.
  • Escalate recurring gaps or missing controls that impact questionnaire responses.
  • Ensure all questionnaires are completed accurately and within customer deadlines.
Requirements
  • 2–4 years of experience completing vendor security questionnaires, working in GRC/compliance, or in a security-related client-facing role.
  • Hands-on experience completing SIG, CAIQ, or custom vendor security questionnaires.
  • Working knowledge of SOC 2 and ISO 27001.
  • Understanding of common security concepts, including:
    • Single Sign-On (SSO)
    • Multi-Factor Authentication (MFA)
    • Endpoint Management
    • Encryption (at rest & in transit)
    • Cloud infrastructure fundamentals
    • Backup & Disaster Recovery
    • Vendor Risk Management
  • Strong organizational skills with the ability to manage multiple requests simultaneously.
  • Excellent judgment regarding when to answer independently and when to involve technical SMEs.
  • Excellent written communication skills.
  • Professional English (written and spoken).
Nice to Have
  • Experience handling a high volume of vendor security questionnaires.
  • Experience with:
    • Conveyor
    • SafeBase
    • Vanta
    • Whistic
    • Trust Center platforms
  • Experience maintaining questionnaire knowledge bases.
  • Experience working alongside Sales or Revenue teams supporting enterprise deals.
  • Certifications such as:
    • CompTIA Security+
    • ISC2 Certified in Cybersecurity (CC)
    • Similar cybersecurity certifications
Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Information Security Analyst
Information Security Analyst

Scale Up Recruiting Partners • Barcelona

Presencial
EUR 83.000 - 124.000
Remote Information Security Analyst — Vendor Risk & GRC
Remote Information Security Analyst — Vendor Risk & GRC

Scale Up Recruiting Partners • Madrid

Presencial
EUR 60.000 - 95.000
Remote InfoSec Analyst: Vendor Security & Compliance
Remote InfoSec Analyst: Vendor Security & Compliance

Scale Up Recruiting Partners • Barcelona

Presencial
EUR 83.000 - 124.000
Information Security Engineer
Information Security Engineer

Comoro Ltd • Barcelona

Presencial
EUR 70.000 - 90.000
Senior Information Security GRC Analyst
Senior Information Security GRC Analyst

OneTrust • Madrid

Híbrido
EUR 55.000 - 75.000
Healthcare coverage
Equity RSUs
Annual performance bonus opportunities
+3
Information Security Assurance analyst
Information Security Assurance analyst

OneTrust • Madrid

Híbrido
EUR 50.000 - 70.000
Healthcare coverage
Flexible PTO
Equity RSUs
+3
InfoSec GRC Analyst: High-Volume Security Questionnaires
InfoSec GRC Analyst: High-Volume Security Questionnaires

OneTrust • Madrid

Híbrido
EUR 50.000 - 70.000
Healthcare coverage
Flexible PTO
Equity RSUs
+3
Information Security Lead
Information Security Lead

Loyal Guru • España

Híbrido
EUR 60.000 - 80.000
Access to wellbeing benefits
Discounts on gyms and fitness activities
25 days of paid vacation
+1
Senior Application Security Engineer
Senior Application Security Engineer

LeoVegas Group • Málaga

Híbrido
EUR 70.000 - 100.000
Hybrid work policy
Workation benefits
Wellness contribution
+7
Cyber Security Analyst
Cyber Security Analyst

Graphic Packaging International • Igualada

Presencial
EUR 42.000 - 68.000